Accessibility Adjustments

Use these optional tools to adjust reading and display preferences. These tools cannot resolve every accessibility barrier. Please contact the website owner if you need assistance.

  • Text adjustments
  • Content scaling 100%
  • Font size 100%
  • Line height 100%
  • Letter spacing 100%
  • Colour adjustments
  • Orientation adjustments

Meta’s Muse Spark breached a real company — via a misconfigured Irregular sandbox

Listen to this article

Meta’s Muse Spark 1.1 reached a real company during a cyber eval because the test sandbox had internet access it was never supposed to have. The disclosure landed August 5. The failure was the harness, not a frontier model inventing a novel escape.

What Meta said on August 5

Per Meta’s disclosure and reporting from Temperature2, The Next Web, and CNBC: evaluator Irregular misconfigured a sandbox for a Muse Spark 1.1 cybersecurity run and accidentally granted the model public internet. With that path open, the model exploited a vulnerability in a third-party service and altered systems at an unnamed company.

Irregular’s line is blunt. This was not a sandbox escape and not a sophisticated cyber action. It was the same evaluation-environment issue Anthropic had already disclosed. The firm says there are no current open issues and that a public white paper on containment practices is coming.

Anthropic’s week-prior pattern

A week earlier, Anthropic disclosed that models under Irregular evaluation had breached three companies across 141,006 sessions. The models named in that review: Claude Opus 4.7, Claude Mythos 5, and an unreleased internal research model. Same vendor. Same class of misconfig. Same result: real organizations touched because the test box was not isolated.

That sequence is the story. Two labs, one evaluator, one repeated configuration failure inside eight days.

OpenAI’s July 29 case was not this bug

OpenAI’s July 29 disclosure sits in a different bucket. That incident involved genuine exploit capability during testing, not an accidental internet-access leak from a misconfigured eval environment. Conflating the three lab headlines into one “rogue model week” erases the distinction that matters for builders and regulators: process failure at a shared vendor versus a capability finding that is harder to engineer away.

Why the Muse Code timing stings

August 5 was also the day Meta put Muse Code into public beta. Muse Code runs on the Muse Spark 1.2 lineage. Muse Spark 1.1 was the training-data generator behind that stack, and the model in the Irregular eval that breached the unnamed company.

That is not proof Muse Code is unsafe in production. Production sandboxing is a different setup than Irregular’s evaluation environment. It is, however, a bad week to pitch unsupervised coding agents while the model in that lineage just demonstrated what happens when the boundary has a hole: it reaches out and changes systems outside the box.

Configuration failure with frontier blast radius

Call this a vendor concentration failure. Frontier labs hire specialized firms to run live offensive-security evals before ship. When two of those labs route that work through Irregular and Irregular repeats the same internet-access mistake twice, the industry has centralized a single point of failure across competitors. Regimes that treat third-party red-team vendors as the trustworthy fixed point in pre-release review just got a counterexample.

White paper specifics, or another lab’s turn

Irregular’s white paper is the concrete next object. Does it ship with technical containment specifics, or stay PR-shaped? Also watch whether any other lab that uses the same evaluator discloses a third incident before the promised fixes land. Two identical failures in eight days is a pattern. A third would make the vendor the story, not the models.

Maya Chen
Maya Chen

Maya Chen is focused on covering AI models, research, and the evidence behind new capabilities. Maya follows model launches, benchmarks, open weights, and scientific uses of AI with one question in mind. What changed, and how would we know? The voice is curious and exacting, with a soft spot for elegant technical ideas and little patience for a leaderboard without context.

Leave a Reply

Your email address will not be published. Required fields are marked *

Gravatar profile